Security reductions
Mar. 15th, 2007 07:24 amFor the three or so cryptographers on my friends list:
The Goh-Jarecki-Katz-Wang DDH-based signature scheme not only has a tight reduction to the hardness of DDH - it also has a loose reduction to DL using the forking lemma in the same way as Schnorr. I mention this because it's currently my favourite scheme, and the authors didn't know about the reduction...
The Goh-Jarecki-Katz-Wang DDH-based signature scheme not only has a tight reduction to the hardness of DDH - it also has a loose reduction to DL using the forking lemma in the same way as Schnorr. I mention this because it's currently my favourite scheme, and the authors didn't know about the reduction...
no subject
Date: 2007-03-15 09:34 am (UTC)no subject
Date: 2007-03-15 09:45 am (UTC)no subject
Date: 2007-03-15 10:29 am (UTC)no subject
Date: 2007-03-15 01:08 pm (UTC)has a tight reduction to the hardness of DDH
Saucy!
no subject
Date: 2007-03-15 04:58 pm (UTC)no subject
Date: 2007-03-15 06:03 pm (UTC)You may be interested to note that it's carefully engineered to give the same signature for a given message every time, which helps the security reductions...
no subject
Date: 2007-03-15 09:11 pm (UTC)no subject
Date: 2007-03-16 12:55 am (UTC)no subject
Date: 2007-03-16 08:49 am (UTC)http://citeseer.ist.psu.edu/ohta98concrete.html
I'll try to write it up when I have time, which might be a while. I'll also include the other observation I had, which was that if you have a hash function H' which maps the group onto itself, then your public key can be (g^x, H'(g^x)^x), which is a third shorter.
no subject
Date: 2007-03-16 08:52 am (UTC)no subject
Date: 2007-03-16 08:56 am (UTC)although actually, I would not preserve that property in an implementation. The reduction is still pretty tight without it, and without it you can do most of the heavy lifting on signature generation in advance.
Saw this, and thought of you :)
Date: 2007-03-16 02:43 pm (UTC)http://blog.wired.com/27bstroke6/2007/03/cryptographer_s.html
no subject
Date: 2007-03-17 01:48 am (UTC)